• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
R Negi & Company, Chartered Accountants

R Negi & Company, Chartered Accountants

R Negi & Company, Chartered Accountants

  • Home
  • About Us
  • Blog
  • Contact Us
  • Income Tax
  • GST
  • Companies Act

SA 402 – Audit Considerations Relating to an Entity Using a Service Organisation

February 21, 2026 by CA Reema Negi

SA- 402

Introduction

SA 402 applies when an entity uses a service organisation to perform functions that are relevant to financial reporting. These services may include payroll processing, cloud accounting, IT infrastructure, data management, or transaction processing.

This Standard explains how the auditor applies SA 315 (Identifying and Assessing the Risks of Material Misstatement) and SA 330 (Responses to Assessed Risks) in situations where activities are outsourced.

When an entity depends on a third party for critical processes, the auditor must evaluate how those services affect internal control and financial statements.

Objectives of the Auditor

The auditor must achieve the following objectives:

1. Obtain an Understanding of the Services

First, the auditor obtains a clear understanding of:

  • The nature of services provided by the service organisation
  • The significance of those services to the user entity
  • The impact of those services on internal control relevant to the audit

The auditor uses this understanding to identify and assess the risks of material misstatement.

2. Design and Perform Responsive Procedures

After assessing the risks, the auditor designs and performs audit procedures that directly address those risks.

Accordingly, the audit approach must reflect the level of reliance placed on the service organisation.

Understanding Internal Controls at the Service Organisation

The auditor evaluates:

  • Controls established at the service organisation
  • The interaction between service organisation controls and user entity controls
  • Complementary user entity controls that management must implement

In many engagements, the auditor may obtain evidence through:

  • Type 1 or Type 2 service auditor’s reports (such as SOC 1 reports)
  • Direct communication with the service organisation
  • Additional substantive or control testing

However, even if the auditor considers the service auditor’s work, the user auditor retains full responsibility for the audit opinion.

Risk Assessment and Professional Judgment

The auditor applies professional skepticism while assessing:

  • IT general controls
  • Automated processing systems
  • Data security and cybersecurity risks
  • Outsourced financial reporting processes

If the service organisation processes significant transactions, the auditor increases the depth of testing and documentation.

Therefore, proper evaluation of third-party risk forms a critical part of audit planning.

Inability to Obtain Sufficient Appropriate Audit Evidence

If the auditor cannot obtain sufficient appropriate audit evidence regarding the services provided by the service organisation, the auditor must modify the opinion in accordance with SA 705 (Modifications to the Opinion in the Independent Auditor’s Report).

Depending on materiality and pervasiveness, the auditor may issue:

  • A qualified opinion, or
  • A disclaimer of opinion

Thus, access limitations or inadequate evidence can directly affect the audit report.

Reference to the Work of a Service Auditor

When Expressing an Unmodified Opinion

The auditor shall not refer to the work of a service auditor in the audit report when expressing an unmodified opinion unless law or regulation requires such reference.

If law or regulation requires reference, the auditor must clearly state that such reference does not reduce the auditor’s responsibility for the opinion.

When Explaining a Modified Opinion

If the auditor refers to the service auditor’s work to explain a modification, the report must clearly indicate that the reference does not diminish the auditor’s responsibility.

Professional accountability always remains with the user auditor.

Documentation Requirements

The auditor must document:

  • The understanding of the service organisation and its environment
  • Identified risks of material misstatement
  • The basis for reliance on service auditor reports, if any
  • The nature, timing, and extent of audit procedures performed

Clear documentation supports audit quality and compliance with professional standards.

Conclusion

SA 402 ensures that outsourcing does not weaken audit assurance. The auditor must understand the services performed by the service organisation, evaluate related controls, assess risks, and design appropriate audit procedures.

Even when a third party performs significant functions, the user auditor remains fully responsible for expressing an independent and professional audit opinion.

Filed Under: Companies Act

Primary Sidebar

Latest Posts

  • Reverse Charge Mechanism (RCM) Under GST: Complete Guide August 22, 2026
  • GSTR-1 & GSTR-3B Filing: Step-by-Step Guide August 21, 2026
  • GST Due Dates 2026: Complete GST Filing Calendar & Compliance Guide August 20, 2026
  • How to Calculate Tax on Freelancing Income in India August 19, 2026
  • GST on Job Work: Rates, ITC, Rules & Compliance August 17, 2026
  • Tax on Fixed Deposit Interest: TDS & Income Tax Rules August 14, 2026
  • Foreign National PAN Card Application: Complete Guide for India August 12, 2026
  • Marginal Relief in Income Tax: Thresholds, Surcharge and Examples August 11, 2026
  • Income Tax Refund Delayed? Reasons & What to Do August 8, 2026
  • Which ITR Should You File: Belated or Revised? August 6, 2026
  • Updated Income Tax Return (ITR-U): Complete Guide for Taxpayers August 5, 2026
  • GST on E-Commerce July 27, 2026
  • GST on Import Services July 25, 2026
  • Capital Gain Exemptions Under Income Tax Act, 2025: Complete Guide July 24, 2026
  • Complete ITR Due Date Calendar 2026 July 21, 2026
  • GST on Rent: Rate, RCM, Exemptions and ITC Explained July 18, 2026
  • ESOP Taxation in India: When and How Are ESOPs Taxed? July 16, 2026
  • NRI Income Tax Return Filing in India: Complete Guide July 15, 2026
  • How to Calculate Capital Gains Tax in India: Step-by-Step Guide July 14, 2026
  • Mutual Fund Taxation in India: A Complete Guide for Investors July 11, 2026

Featured posts

Reverse Charge Mechanism (RCM) Under GST Complete Guide

Reverse Charge Mechanism (RCM) Under GST: Complete Guide

GSTR-1 & GSTR-3B Filing Step-by-Step Guide

GSTR-1 & GSTR-3B Filing: Step-by-Step Guide

GST Due Dates 2026 Complete GST Filing Calendar & Compliance Guide

GST Due Dates 2026: Complete GST Filing Calendar & Compliance Guide

How to Calculate Tax on Freelancing Income in India

How to Calculate Tax on Freelancing Income in India

GST on Job Work Rates, ITC, Rules & Compliance

GST on Job Work: Rates, ITC, Rules & Compliance

Tax on Fixed Deposit Interest TDS & Income Tax Rules

Tax on Fixed Deposit Interest: TDS & Income Tax Rules

Foreign National PAN Card Application Complete Guide for India

Foreign National PAN Card Application: Complete Guide for India

Marginal Relief in Income Tax Thresholds, Surcharge and Examples

Marginal Relief in Income Tax: Thresholds, Surcharge and Examples

Income Tax Refund Delayed Reasons & What to Do

Income Tax Refund Delayed? Reasons & What to Do

Which ITR Should You File Belated or Revised

Which ITR Should You File: Belated or Revised?

Updated Income Tax Return (ITR-U) Complete Guide for Taxpayers

Updated Income Tax Return (ITR-U): Complete Guide for Taxpayers

Copyright © 2026